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fcLXf4(m,r)(^5H955^ia^L, L «Bf ^C^^P^^T)., 
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[0038] NTRUB£-S§-;^0#^ ^J^{ftVh^Jw^Btf^cDfc* yh^IJi^^OtVh^J^^ 

[0039] gff#f*e£g{tUt^ eZm^LXm%nZ> 0 ±&l,tz£5lc£(m)<DmMlMrte 
mTC^SmXfoZfali, r&mTC-fZo ^LT, w = m||rKJ:«?w£m7Gl-5o w&&-%'&, 
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[0048] m^xAxmm2oiiz£m^tmw2oo^i*z.t>tv, m^tmmo 

OtC«NTRUt[^kgl5202, SU&m5ngfl203, ^&§li&Atf>M&g|S204. OAEP+ 
^^lfi5205^if(Z)7 o D-fe^^^$tb-CV^ o m^fcSg200K£9£j&$;ft,#:¥ 

[0049] 1. 

[0050] H4I4 X *l^^ffifcfclt««i^^llS**i-7a-^^-h-T?ife5 0 

g300te N JEmmp, q, NSrtD, ««3E*i:LT^H-t-5. ±KBLfcNTRUSt^-^ 
tmm\^ R = Z[X]/(X N -l)<hU R<^7CuT-fco-Cu<D#^icO#iC(05*)ai®^iT*b 

R^^-^L, L , L , L «r8U5C*7 l y:/Sll). 

f g r m 

[0051] zbizm&smmm* oAE^^^^xnmvtiXoK. /<9*-*k, k , k 

o 

***>&t£M&:k, k , k WOES*, ^o, k + k ^ k ^ L^«fci- 0 L« 

1 0 1 0 1 

L X L 07C(D^T*fe5 0 n = k - k -ktU 

m r 0 1 

Gfi.ktVhOtV^JfCntVhtDtVh^J^^-fr^N^a.gi^, 
H'te, n+k o l^yh(^fcV^^Jlck l lfy^Ofc'y^^J^iS$-B:•5/^yv'^Bi^:, *5«fcl* 
Hte, n+k l^hcDfcVh^JKk^VhcDt? y m&ttl&Z-&&^>a.mki:1rZ {Xt 
y^S12) 0 

[0052] $b^, m^mmn.wm^*®&.-*z> (^^^si3). ^mw^Attktv 
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[0053] (l)Att¥l+-C*>5rt 

(2) A*3J:WE-©iS»^<feds#3gS;i^ra-c^|j[-C#5-i : 

(3) «P^kBB«*E(ni, r)fcUy$, ¥&E:A(X)^L -#fatt§B*rC*>5£*( 

e 

e 

[0054] ma&tmnm. NTRutmmMmxm±^mn-r^ 0 -tt^ibht>h^ l 

f s 

*»feg*9^AiaRu, h = fg mod q ttz>o f, gzm&mtu h&mmtrs 
xy^si4) 0 ms&mmm. r, g&s&^eii^g302f;iM«K^u*7 i s> 

:^S15), NTRU©4*HMfc _hae^>y^H»*5 ( J:tfSEiftB8*(p. q, N, L, L , L . L , 

f g r m 

k, k o . k , g, h*. h, a, ti&temmmmmmmoiizfeMvx&Mttix^yzfs 

16) a 

[0055] 1. 2)Bf^k^Jll 

[0056] 05«, mmMBmKtevm^tmmz^-t7v~^~-hx~&z> 0 v&mm 
mmmmmmm3oifribtefflmmp, Q , n, l. l , l , l , k, k , k , g, h', h, a, *> 

f g r m 0 1 

[0057] ffib k\fy htf>fcVh?IjR£7^yAlr igtf (*7^:7 P S23) , OAEP+^§P102 
tt, G(R)i:M©tVhSOS^^^ra|p s 0 ^tf^L, s ! =H'(R||M)£fH*U s = s^s'tL 
. ££>K, t^H(s)tR^>tVh^O#^e<3^a^j < !;LT, w = s||t££f£1-5C£-C, 
SrOAEP+/-?^>-r-rS (*7^S24) 0 

[0058] £&m03ra3g&§§SfcA«rfl3V*-C\ (m, r)=A(w)Kl<fco-C, w£2o<DtfVH3aj 

m*3j;Ufr[C^m-r-5(X^^S25) 0 r^T'ii, w^^ftJL-CM^^h^J^m, 
^^fyh^Jfertl-S. ^LT, NTRUBff^kflBJl04l4, e = phr + m mod q&tUT 

gl05d^tB^-T-5 C*7^S27) 0 
[0059] 1. 3)«#fls^Jfi 
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[0060] 13614, mimMtemiz&v^^k^m&mir7v-^-hX'hz> 0 -trrm.^ 

ltmm200te\fe%r$:A£)mm201frb\fe^Xe$;%:Vm (*7^:/S3l) , i^cVNT, 

[0061] NTRUtgM202l4, £rHSHf ^ioirjt^SI^ V vc\ NTRUBf^Tj S^I^K 
Bt^^e^m^k^aSr^T^o -t-^t>*> % fe = pgr + fin mod qSrfr^U f, g, r, m&Z 
tl^tbU L N L , L <D7C~eh5>^bfrt>fe = pgr + fmXhZ><DX\ fe (mod p) = m (mod 

f g r m 

p)£fr»t-5w<!;#-et. m^L (DTcT'fcSrtd^m = m (mod p)tj:(DX, m^TcT 

m 

#S(^5/^S33) 0 

[0062] £fc, SL$^7cg|5203f3\ fe = pgr + fmX3b5<DX, r = (fe - fm)/pgtC<fct)r£r^7C-r 
5C*7 i $/:7 ,> S34) 0 

[0063] WMmb204\^m&%UK<Dmtm:m\ ^X. A'\m,v)\Z.^. w = s||t = s ||s 

0 

i l|t^5Ei-5(^X5/^S35) 0 m^X, OAEP+jS»^M205{4, H(s)a<DKVr-&£> 

-fZZ.t\C£r)M$:&7n-f% (X^yS36) 0 
[0064] g#t£, ^y^^aSjE^T-feSri^A^ = HXR||M)2Wc£;ft^a^;W£j:o 

r^JKL(^x^S37) % E^Tfcnfi¥^M^W^L(^y^S38), E^T^ft 
^fiBt^el4^E^Bf^i:L-C± £^-^5 (*XS/:/S39) 0 

[0065] 2. m2mmmm 

^(-li^^g300[cJ:^«$^c^^b/^^bt^i£:^^§H^^?rf5ti-r 

sennit mmmmm3oi % m^-m^m^mmmm mzmm-rzmmmmmmm 
302&m-rz o 

[0066] W-M. ¥^A^^ei01{Cj;«3fHP^bilM400^4-xbn, Pf -5H££§400K 
ttSL^^gR401, m&mm^tn402. OAEP+^&gfl403, g£&Mi£AK 
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[0067] Bf-^te, Bt^A^^201 [Z. ^m^mM 500^J*z_btl. ^-^^50 
OKteNTRU^-^fcgBSOl, aM5£SP502, ^&H9$CAtf>$^&SB503, OAEP+ 

[0068] 2. 

[0069] 08i* x mmMMmiz&vzm£&^m&7f:i-7V'-^ j r--hX'$>z> 0 m±&m 

tmmc, R = Z[X]/(X N -1)£U RC»7nu-rfcoTu<^#^ic^#:W5^a^^i-X?b 

ffias-U •ftfe<Dt<D^o-Cfc5t><^^<^-a' (RV&&M&) &U&,b)xmirb<DbU 
R^SP^-a-L, L , L, L £Ife5(^s>:/S41) 0 

f g r m 

[0070] £<bim$Lf&mm&. oAEP+s^^yttxmwvitz.?^ ^>-*k, k , k 

o 

*nk<D£?i£M&:k, k , k itiEmm. a>o N k + k ^ k ^ L&mtc-to ^x\ u± 

1 0 1 0 1 

L X L <Dn<DmXhZ> 0 n = k-k -ktU 

m r 0 1 

Hli, n+k tVh<^fcVh^J(ck o tVhotVh^J^^j£$*^Ny iy3.ii^:<t-rs 
5/^S42) 0 

[0071] £e>K. #^^mif*^^HicA^^-t-5 (*X2/^S43)o ^^IS^Afi, ± 

m r 

[0072] (DAtt^tfeSCi: 

(2) a *s xx^t^m^m^m^mmx^nx^zt 

(3) Bf^Cii^E(ni, r)£L7c:R#, ^&E:A(X)^L fcfc, -jjfa&MmX&Z^bi 

e 

c 
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[0073] iKiim, mRutmm<Dxmx*m*E&L&mfti-z>o ^^hLa^pk, l 
frbg&^yMzW). h = f * g mod q ffz> 0 f, g£§Hfc&tu h&4*ra«ti-3. «t 

[0074] $e>|^ % It^^gltt, M-r-5*iiSSSSBf^S;ES:*^L(^5'yS45) , 

NTRU<D^$§& X ±3&^i'~wm$&xm&mkij>, q. N, L, L , L , L , k, k , k , 

f g r m 0 l 

g, h', h, a, \i)*<&mmn&famwzoi\z&mjx<ikmtt{y^yzfs4G) 0 
[0075] 2. 2)m^tmm 

[0076] H9tt, m2mmmm^tfm^itmm^-r^-^-h-vhZo ntmm 

Wttf*|Btt»K301*»fe^Hlffif«p, q, N, L, L , L , L , k, k , k , G, H\ H, A,*5«fc 

f g r m 0 1 

[0077] SMV^T. a^l§^^401^fflVN-C^g|iBt-^->fk|fP402«ntf5/h<D^>h^jM^9>- 
54) D r^T% E M 00tt. M^Ht^LT¥AXSr*ii«iBt^^E^^oTII&-§-'fbbfct) 

[0078] >T, k o fcVh(OtVh?IJR?r5^A(rSUf C*^5>:/S55) „ OAEP+^^403 

tt, G(R)^MOfcVh^(D#ftfeW^TOs°^fi-^b, s=H'(R||M)&H-*U s = sIls^L 

SrOAEP+^v^iZ-f 5 (^s/:/S56) „ 
[0079] £&Hi£A£«i:5g?&g&404tt, On, r ) = A(w){^fcoTw^2oOlf5/h?lJm 

*5j;tFr^^^-r5 (*^y:/567) 0 CwX'fi, w^2^fJUTHfj^tVh^J ; Srm. ^ 
¥<DfcVh?!l£r<t-t-5 0 ^Tb-C, NTRUBf -5Hfc8B405W\ e = phr + m mod q^ff^i" 
S^i-CNTRUHt-f-fbSTfTV^ (^^S58) » ^c$*bfcffif-§-Aet*ii«iHf#©l« 

[0080] 2. 3)«#-fk#«S 

[oo8i] 0io«, ^2^^^{djo^m-§-ft^«i^-r7n-^^-h-cfc5o *-*■«-§■ 
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[0082] NTRUm^kSP501«, &iif#*5i^«|^V^, NTRUBf -^^l^tH 
{-Bf^-^eO^^k^S^fTPo 1~ti:t>h. fe = pgr + fin mod q£fr^U f, g, r, mtf* 
-^rtb^ttL > L % L % L <Dyz,X'h%Zbt>*bte = pgr + fmT'&SO-C, fe(mod p) = m 

i g r m 

(mod p)?rm-^1-5^<b^^, m^L (DytX-hZZtfabm = m (mod p)&<DT\ 

m 

7C-e#5 0*ry:/S63) o 
[0083] SUScm7ngB502 fi % fe = pgr + fmXhZ><DX* s r = (fe - fm)/pgl£ it)r^55-f 

S(^s/^S64) 0 

[0084] «&g|5503{4. A"W)KJ:!K w = s||t = sjlsjltft*^* (X^y^S65) 
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